The AI your team is already using
Shadow AI is not a discipline problem, it is people finding tools that help. The risk is that nobody knows what has been sent where. How to find out, and what to do about it without banning anything.
If your business has not chosen an AI tool, that does not mean nobody is using one. Someone has pasted a client email into a chatbot to get a politer version back. Someone has dropped a contract in to ask what a clause means. Someone has a browser extension that summarises meetings, installed without asking, because it saves them twenty minutes a day.
This is shadow AI: capable tools arriving from the edges, brought in by people trying to do their jobs faster. It is worth understanding before you decide what to do about it, because the instinctive response is the wrong one.
Why it happens
Not recklessness. The tools are free, they are one browser tab away, and they are genuinely good at the tedious part of a job. Waiting for a company decision that may never come costs a person real time every week, so they stop waiting.
Nearly every case we see comes down to the same thing: there was no sanctioned option, so people found their own.
What actually goes wrong
The problem is not that AI is being used. It is that nobody knows what has been sent where.
Start with the accounts. The consumer version of a popular AI tool and the business version are often the same underlying model on very different terms. The consumer one may use what is typed into it to improve the product. The commercial one contractually does not. Your team is almost certainly on the first.
Then the record. If a client asks whether their information has been through an AI system, you need to be able to answer. So does an insurer, an auditor, or anyone assessing you as a supplier. Personal accounts leave you with nothing to check.
The tool is rarely the problem. The problem is that it sits on somebody's personal account and nobody knows what has gone into it.
Then departure. The account belongs to the person, not the business. When they leave they take the history with them, including whatever of yours is in it, and you have no way to revoke access to something you never had.
And finally judgement. A draft that goes to a client without anyone reading it properly is a risk whether a person or a model wrote it. That is the same question of what a system is allowed to decide alone that any deliberate AI project has to answer.
Why a ban does not work
Banning the tools moves them onto personal phones. You lose the little visibility you had, the people who were open about it go quiet first, and you give up the productivity your team found on their own. A rule that everyone breaks quietly is not a control, it is a comfort.
What to do instead
Find out what is actually in use, and ask in a way that gets a truthful answer. Say plainly that you want to know what is helping, not who to blame. The list is usually longer than expected and often includes something genuinely worth keeping.
Give people a sanctioned option on a business account. This is the step that does most of the work. People use the approved tool when the approved tool is as good as the one they found, and quietly keep using theirs when it is not.
Write down the handful of rules that matter, on one page somebody will actually read. What can go in, what cannot, and what a person has to check before it goes out. Client identifiers, health information, payment details and anything under a confidentiality clause are the usual lines.
Keep a register of approved tools, what each is used for and who owns it, and give the whole thing a named owner. New tools appear constantly, and an unowned policy is stale within months.
The short version
Assume it is already happening. Find out what, give people something sanctioned that is at least as good, and write down the few rules that matter. The goal was never to stop your team using AI. It is to make sure the version they use is one you have agreed to.
Want to find out what is actually in use?
The Shadow AI Audit is twenty-four questions and about fifteen minutes. It gives you a risk score, your top five risks ranked, a 30-day fix list and an AI policy you can circulate this week.
What Australian privacy law asks of you
Whether the Privacy Act applies to your business, the four principles an AI project actually touches, and the disclosure rule for automated decisions arriving in December 2026.
Cloud AI, or your own server?
Keeping AI in-house feels like the safe choice, and sometimes it is. But the decision turns on what your obligations actually say and how steady your volume is, not on which option sounds more secure.